See the domains from that IP involved in this campaign: http://urlquery.net/report.php?id=1498310199996
The scan of the address: https://www.virustotal.com/pl/url/1750f70d5cf2e5117d0764ff05002cc4c06503be2a6aa77cce5e043e25dcabb4/analysis/1498312516/
and file: https://www.virustotal.com/pl/file/ecab159db840c768755641bc3841579e27dd3d74317d334387858704aff4cc42/analysis/1498269254/
avast detects as Win32:Adware-gen [Adw]
polonus